Nova Patents
US8214398B1

Role based access controls

Summary by NHIP

Role-Based Access Control Method

The method loads a policy module and generates a role profile by analyzing user tasks via a role shell. The profile is stored in the operating system layer, refined using logs, and enforced by constraining the role shell to facilitate communication between system and application layers.

Claim Score by NHIP

Read claim 12, the broadest

Abstract

Role-based access controls improve user access in a computer system. A profile associated with a role is generated. The profile is enforced with respect to one or more users associated with the role. Optionally, the profile is generated based at least in part on a user interaction.

US8214398B1, drawing sheet 1
Sheet 1 of 9

Term

Projected expiry 3 March 2027.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

18 claims: 3 independent, 15 dependent

  1. 1
    A method of providing access control in a computer system arranged to include an operation system layer and an application layer, the method comprising:loading a policy module within the operating system layer;generating a profile associated with a role within an organization by analyzing with an analyzer tasks performed by a user associated with said profile using a role shell, and determining based upon said analyzing a set of rules that define said storing the profile within the policy module in the operating system layer;enforcing the profile with respect to one or more users associated with the role;associating the role shell with the role;and facilitating communication between the operating system and application layers using the role shell.
  2. 12
    Broadest claimClaim Score 68, broad(NHIP)A system of providing access control comprising a processor, coupled to a memory, configured to:load a policy module within an operating system layer;generate a profile associated with a role by analyzing with an analyzer tasks performed by a user associated with said profile using a role shell, and determining based upon said analyzing a set of rules that define said profile;enforce the profile with respect to one or more users associated with the role;store the profile in the policy module in the operating system layer;associate the shell with the role;and facilitate communication between the operating system layer and an application layer using the role shell.
  3. 18
    A computer program product to provide access control, the computer program product being embodied in a computer readable medium and comprising computer instructions to:load a policy module within an operating system layer;generate a profile associated with a role by analyzing with an analyzer tasks performed by a user associated with said profile using a role shell, and determining based upon said analyzing a set of rules that define said profile;store the profile in the policy module in the operating system layer of the computer;associate the role shell with the role;facilitate communication between the operating system layer and an application layer using the role shell;and enforce the profile with respect to one or more users associated with the role.